5.9
CVSS CVSS_V3
Status
Impact
This vulnerability relates to 'guava', one of spark's dependencies. Remediating this requires upgrading guava to v24.1.1 or higher, which is a significant version upgrade. Spark has already upgraded to a fixed version in the main branch, but this is yet to be backported to the spark v3.5 release. Attempting to upgrade guava results in build issues. For more information, see:
Status